การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Cloud Security

Canva Suffers Data Security Incident Linked to Third-Party Vendor

FORTSECURE GLOBAL· 2026-09-24🛰 DataBreaches.net
#Cloud Security#Data Breach#Supply Chain Security#Vulnerability

Canva and other global companies have been impacted by a security breach originating from a compromised third-party Salesforce instance.

The Risks of Third-Party Integrations A threat actor group identified as 'The Seven Deadly Sins' has claimed responsibility for a security breach targeting Canva and several other organizations. The attack vector was identified as a compromised Salesforce instance belonging to a third-party vendor utilized by the affected companies. This incident highlights a growing trend where cybercriminals leverage the interconnected nature of cloud-based SaaS ecosystems to gain unauthorized access to secondary targets. Because many platforms share data or configurations, a single failure in a vendor's security posture can create a domino effect across their customer base. ## Securing the SaaS Supply Chain To mitigate risks associated with third-party vendors and cloud integrations, organizations must adopt a rigorous Vendor Risk Management (VRM) program. Initially, security teams should mandate comprehensive security audits of any vendor that stores or processes corporate data, ensuring they adhere to stringent access control standards. Secondly, companies should practice the principle of least privilege by configuring cloud integrations such as Salesforce to have read-only access where possible, rather than full write or administrative privileges. Regularly reviewing API permissions and removing stale integrations is essential to minimizing the attack surface in modern cloud environments.


แหล่งที่มา: DataBreaches.net เผยแพร่ครั้งแรก: Wed, 23 Sep 2026 20:59:47 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: DataBreaches.net

เผยแพร่ครั้งแรก: Wed, 23 Sep 2026 20:59:47 +0000

บทความต้นฉบับ: https://databreaches.net/2026/09/23/canva-hacked-via-vendors-salesforce-instance-other-customers-affected-as-well/

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog